Kerberoasting Assessment Report Template
Assessment Details
| Field |
Value |
| Engagement ID |
[ID] |
| Domain |
[domain.local] |
| Assessment Date |
YYYY-MM-DD |
| Assessor |
[Name] |
| Tool |
Impacket GetUserSPNs v0.11.0 |
Summary
| Metric |
Value |
| Total Kerberoastable Accounts |
XX |
| Cracked Passwords |
XX |
| Privileged Accounts Cracked |
XX |
| Domain Admin Compromise |
Yes/No |
Kerberoastable Accounts Inventory
| Account |
SPN |
Privileged |
Password Age |
Cracked |
Risk |
| svc_sql |
MSSQLSvc/SQL01:1433 |
DA Member |
365 days |
Yes |
Critical |
| svc_web |
HTTP/WEB01 |
No |
180 days |
Yes |
High |
| svc_backup |
HOST/BACKUP01 |
Backup Ops |
730 days |
No |
High |
| svc_exchange |
exchangeMDB/EX01 |
No |
90 days |
No |
Medium |
Attack Chain
Findings
Finding 1: Kerberoastable Domain Admin Service Account
| Field |
Value |
| Severity |
Critical (CVSS 9.8) |
| Account |
svc_sql@corp.local |
| SPN |
MSSQLSvc/SQL01.corp.local:1433 |
| Password Cracked |
Yes (weak password) |
| Impact |
Full domain compromise via DCSync |
| MITRE ATT&CK |
T1558.003 -> T1003.006 |
Remediation:
- Immediately reset svc_sql password to 25+ random characters
- Remove svc_sql from Domain Admins group
- Convert to gMSA:
New-ADServiceAccount -Name svc_sql -DNSHostName sql01.corp.local
- Disable RC4 encryption for this account
Finding 2: Multiple Service Accounts with Weak Passwords
| Field |
Value |
| Severity |
High |
| Accounts |
svc_web, svc_iis |
| Time to Crack |
< 2 hours |
| Impact |
Lateral movement to web servers |
| MITRE ATT&CK |
T1558.003 |
Remediation Plan
Immediate (0-48 hours)
Short-Term (1-2 weeks)
Long-Term (1-3 months)